CVE-2024-13484: Openshift-gitops-operator-container: namespace isolation break

Published Mar 13, 2024
·
Updated

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

Other sources

Currently argocd applies the label openshift.io/cluster-monitoring to all namespaces that deploy a ArgoCD CR instance. This then allows the namespace to create a rogue PrometheusRule that can then have adverse effects on the platform monitoring stack. As the label is applied the rule is rolled out cluster wide.

This gives anyone who has argocd instances deployed a way to escalate out of their namespace isolation and affect the entire cluster.

Red Hat

Affected Software

2 affected components
ArgoCD ArgoCD
go/github.com/redhat-developer/gitops-operator<=1.15.0

Event History

Mar 13, 2024
Data Sourced
via Red Hat·01:43 PM
DescriptionSeverityAffected Software
Jan 28, 2025
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-13484?

CVE-2024-13484 has been assessed as a medium severity vulnerability due to its potential to affect platform monitoring.

2

How do I fix CVE-2024-13484?

To mitigate CVE-2024-13484, update ArgoCD to version 2.10.4 or later, which addresses this vulnerability.

3

What impact does CVE-2024-13484 have on ArgoCD?

CVE-2024-13484 can allow the creation of rogue PrometheusRules in namespaces, negatively impacting monitoring capabilities.

4

Is CVE-2024-13484 exploitable in all deployments of ArgoCD?

CVE-2024-13484 is exploitable in all deployments of ArgoCD versions up to and including 2.10.3.

5

What software versions are affected by CVE-2024-13484?

CVE-2024-13484 affects ArgoCD versions up to and including 2.10.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203